From Anti-Patterns to Best Practices: A Practical Guide to DevSecOps Automation and Security

QCon London 2024

Session

From Anti-Patterns to Best Practices: A Practical Guide to DevSecOps Automation and Security

Wednesday Apr 10 / 03:55PM BST, Mountbatten (6th Fl.)

Abstract

In the modern DevSecOps landscape, teams often struggle to achieve more with fewer resources, leading to the development of counterproductive habits. These habits can significantly hinder the ability to establish effective security programs. Our presentation aims to address these challenges by identifying common anti-patterns based on our experiences and observations in the field. We will highlight the problems associated with these habitual practices and offer concrete, practical solutions.

Throughout this session, we will guide you through the most prevalent anti-patterns identified in our security efforts and observed in other teams. Additionally, we will provide alternatives to these detrimental practices, along with a compilation of free and open-source tools endorsed by the community. These resources are instrumental in reinforcing strong security practices across different organizations. Join us as we delve into a narrative of anti-patterns, best practices, and the extensive potential of automation to enhance security measures.

Interview

I'm the founder of a company in the Security Automation Space and its principal architect/security engineer.  We create solutions that radically improve the efficiency of any security engineering team.

To provide a list of the most common counter-productive behaviors observed by several security teams out there, how to recognize early signs of this and how it can be overcome with a mix of human intervention and automation.

Persona: developers or security folks
Level: medium+ 

Security people are not the police, they are the team's physician.
 

Therefore, they are not there to add checks and balances; they're there to observe and advise on good habits that would lead to a long and healthy product life cycle. Talk to them the same as you'd talk to your physician.

76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon London 2024 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Wednesday 10 April

10:35 Mountbatten (6th Fl.) Session zero trust A Zero Trust Future for Applications: Practical Implementation and Pitfalls Ashish Rajan CISO @Kaizenteq Ltd, Host of "Cloud Security Podcast", and SANS Trainer for Cloud Security, 13+ Years Experience in the CyberSecurity Industry 11:45 Windsor (5th Fl.) Session Ethical AI Trends in InfoSec: Data Minimisation, Autoclassification, and Ethical AI Rachael Greaves CEO & Co-Founder @Castlepoint Systems, Australia's Most Outstanding Woman in IT Security, RegTech Female Entrepreneur of the Year, Women in Fintech Powerlist, Top 100 Innovator, CISM, CISA, CDPSE, & CIP 13:35 Mountbatten (6th Fl.) Session Beyond the Breach: Proactive Defense in the Age of Advanced Threats Michael Brunton-Spall Deputy Director Cyber Policy and Solutions @Cabinet Office 14:45 Mountbatten (6th Fl.) Session Poetry4Shellz – Avoiding Limerick Based Exploitation and Safely Using AI in Your Apps Rich Smith 15:55 Mountbatten (6th Fl.) Session From Anti-Patterns to Best Practices: A Practical Guide to DevSecOps Automation and Security Spyros Gasteratos Founder @smithy.security